// For flags

CVE-2014-5428

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.

Vulnerabilidad de la subida de ficheros sin restricciones en servicios web no especificados en Johnson Controls Metasys 4.1 hasta 6.5, utilizado en Application and Data Server (ADS), Extended Application and Data Server (también conocido como ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, y NxE8500, permite a atacantes remotos ejecutar código arbitrario mediante la subida de una secuencia de comandos de shell.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-22 CVE Reserved
  • 2015-03-29 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Application And Data Server
Search vendor "Johnsoncontrols" for product "Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Extended Application And Data Server
Search vendor "Johnsoncontrols" for product "Extended Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Lonworks Control Server Lcs8520
Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2u
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5520-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5521-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Nxe8500
Search vendor "Johnsoncontrols" for product "Nxe8500"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Application And Data Server
Search vendor "Johnsoncontrols" for product "Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Extended Application And Data Server
Search vendor "Johnsoncontrols" for product "Extended Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Lonworks Control Server Lcs8520
Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2u
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5520-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5521-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Nxe8500
Search vendor "Johnsoncontrols" for product "Nxe8500"
--
Safe